Privacy Policy
Last updated: August 30, 2026
This Privacy Policy describes how Mirrorles ("we", "us", "our") collects, uses, and protects your information when you use our iOS application (the "App"). By using Mirrorles, you agree to the practices described here.
1. Information We Collect
1.1 Information You Provide
Account information. When you create an account, we collect:
- Your email address
- A password, which is securely hashed. We never store your plaintext password.
- An optional display name
If you sign in with Apple, we receive the account information and limited authorization data necessary to authenticate you. We use this authorization data only to disconnect Mirrorles from your Apple account when you delete your Mirrorles account. We do not receive your Apple ID password.
Photos you upload.
- Avatar photos. Photos you upload to represent yourself in the App.
- Garment photos. Photos of clothing items you upload for our AI to identify and add to your wardrobe.
Wardrobe and outfit data. Metadata you provide about your items (name, category, tags, favorites) and the outfits you generate.
Photo metadata (EXIF). Photos taken with a phone or camera typically include embedded metadata such as GPS coordinates, device model, and timestamps. We strip this metadata from your photos at the time of upload, before storing them on our servers. Location data from your photos is not retained.
Subscription and purchase records. If you subscribe to a paid tier through the App, your payment is processed by Apple. We do not receive or store your payment method, card number, billing address, or Apple ID password. From Apple's StoreKit receipt we record only: the Apple transaction ID and original transaction ID; the product identifier you purchased; the purchase date, the current period's expiration date, and any revocation date; the environment (sandbox or production); and whether the subscription is in a free-trial period and whether auto-renew is enabled. We use these records to grant and renew the credits associated with your subscription, to honor refunds reported by Apple, and to provide customer support. We do not use these records for advertising or marketing.
1.2 Information Collected Automatically
- Session information. When you log in, we issue and protect authentication credentials so you can stay signed in.
- IP addresses. We temporarily process your IP address for rate-limiting and abuse prevention. IP addresses are not retained in long-term account records or operational logs.
- AI processing and diagnostic metadata. For outfit generation, garment detection, and garment extraction requests, we record limited usage, cost, performance, status, and error metadata tied to your account for service operation, billing, abuse prevention, and troubleshooting. Operational logs do not contain uploaded photo bytes.
We do not use third-party analytics SDKs, advertising identifiers, or crash-reporting services that transmit data to third parties.
2. How We Use Your Information
We use your information to:
- Operate the App, including generating outfits and extracting garments from your photos
- Authenticate you and keep your session active
- Enforce rate limits and prevent abuse
- Track usage and costs associated with AI processing
We do not use your photos or wardrobe data for advertising. We do not sell your personal information, and we do not sell or share your personal information for cross-context behavioral advertising.
3. How We Share Your Information
We use service providers, including the following, to operate Mirrorles. They process data only for the purposes described below.
3.1 Google Gemini (Google LLC)
- What we send: Garment photos, along with text prompts.
- Why: To identify garments in photos before you choose which items to isolate.
- Training restriction: We do not use your photos or prompts to train AI models. Under our agreement with Google for the paid Gemini API, user-submitted content is not used to train Google's models either.
- Service logging: Google may retain limited prompts and responses for safety and abuse monitoring under its paid-service terms.
3.2 FAL.ai
- What we send: Your avatar photos and garment photos, along with text prompts.
- Why: To isolate selected garments and create outfit images.
- Training restriction: FAL.ai does not use customer API data to train models under its serving terms.
- Temporary processing: FAL.ai processes these materials temporarily to provide the requested feature, subject to its contractual terms with Mirrorles.
3.3 Your AI Data Sharing Choice
Before Mirrorles sends a new photo to Google Gemini or FAL.ai, the App asks for your explicit AI Data Sharing Consent. You can decline and the requested AI operation will not begin. You can withdraw consent for future AI processing at any time by turning off AI Data Sharing in Profile. Withdrawal does not delete photos or outfits already stored in your Mirrorles account; you can use the App's deletion controls separately.
3.4 Apple (Sign-In Provider)
If you sign in with Apple, we receive the account information and limited authorization data necessary to authenticate you. We use this authorization data only to disconnect Mirrorles from your Apple account when you delete your Mirrorles account. Your choice to use Sign in with Apple is governed by Apple's own privacy policy.
3.5 Apple (In-App Purchase Processor)
Subscriptions are sold through Apple's App Store and processed by Apple under its own privacy policy. Apple is the merchant of record for your transaction and is the data controller for your payment information. We receive only the receipt fields described in Section 1.1; we never see your card number, billing address, or Apple ID password. We use limited subscription lifecycle information from Apple to keep your entitlements in sync.
3.6 Infrastructure Service Providers
- What we process: Contracted infrastructure providers host and process the account, image, and operational data needed to provide Mirrorles.
- Why: Private image storage, delivery, and preprocessing needed to operate the App's image features.
- Protection: These providers process data only to provide contracted services to Mirrorles. They may not use Mirrorles user photos for advertising or tracking.
- Access: Access controls are designed to prevent public access and limit user-image access to authenticated owners.
We do not share your personal information with advertisers or data brokers.
4. Data Retention
While your account is active:
- Account data (email, display name, password hash) is retained for as long as your account exists.
- Avatars, saved garments, and saved outfits are retained until you delete them in the App or close your account.
- Source photos used for garment detection and extraction, and their account-linked processing metadata, are retained until you close your account. The App does not currently provide a separate deletion control for a detection source photo.
- Unfinished draft garments and outfits may be removed after they are more than 7 days old when our maintenance cleanup runs. This draft cleanup does not delete saved outfits merely because they are not marked as favorites.
- FAL.ai processing materials are retained temporarily and deleted no more than one hour after processing.
- Session information is retained until you log out or automatic expiration, no more than 30 days after issue.
- Operational and security logs are retained only for as long as needed to operate, secure, and troubleshoot the service. They do not contain uploaded photo bytes.
- Subscription and purchase records (the receipt fields listed in Section 1.1, plus the credit ledger entries that record grants, spends, and refunds) are retained while your account is active so we can honor your entitlements and respond to disputes or refund requests from Apple.
When you delete your account:
- Permanently deleted: your profile and credentials, avatars, wardrobe garments and their images, outfits and their associated images, and session information.
- Operational and security logs: existing log entries may remain for their normal operational lifecycle where needed for security and troubleshooting.
- Retained for subscription ownership and billing integrity: a minimal record containing the Apple original transaction identifier, the former internal Mirrorles account identifier, environment, and deletion time is retained to prevent the same subscription from being claimed by a different account and to resolve billing disputes. Limited billing records may also be retained where needed for billing integrity or legal obligations. These records are not used for advertising or tracking.
Operational backups. Database records may persist in encrypted operational backups for a limited recovery window of up to 30 days before being cycled out. Backups are used only for disaster recovery.
5. Deleting Your Account and Data
You can delete your account at any time from within the App (Profile tab). See Section 4 for the full list of what is permanently deleted and what is retained for limited billing, security, or legal purposes.
Account deletion is irreversible. If you need a copy of your data before deletion, please email the address in Section 12. We will respond within 30 days.
6. Your Rights
Depending on where you live, you may have the following rights regarding your personal data:
- Access. You can view your profile, avatars, garments, and outfits from within the App.
- Correction. You can edit your display name and wardrobe data from within the App. To change your email address, please contact us.
- Deletion. You can delete individual items and your entire account from within the App.
- Portability. You can request a copy of your data by contacting us.
- Objection and restriction. You can withdraw AI Data Sharing Consent for future AI processing from Profile. You can also object to other processing or request we restrict it by contacting us.
EU, UK, and EEA residents have rights under the GDPR. California residents have rights under the CCPA, including the right to know what personal information we collect, the right to delete it, and the right not to be discriminated against for exercising these rights. Residents of other US states with comparable privacy laws have the same rights under those laws.
To exercise any of these rights, email us at the address in Section 12.
7. International Data Transfers
Our servers are located in Germany, within the European Economic Area. Your account data and photos are stored and processed there.
Our third-party AI processors (Google Gemini, FAL.ai) may process data in the United States and other countries. When personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses and the processors' own data processing agreements to provide appropriate safeguards.
8. Security
We use technical and organizational safeguards designed to protect your information, including secure credential handling, encryption in transit, access controls, restricted access to user images, input validation, and abuse-prevention measures.
No system is perfectly secure. If we detect a breach that affects your personal data, we will notify you as required by applicable law. For users in the EU, UK, and EEA, we will notify the relevant supervisory authority within 72 hours of a confirmed breach that poses a risk to your rights, consistent with GDPR Article 33.
9. Children's Privacy
Mirrorles is not intended for children under 13. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at the address in Section 12 and we will delete it.
If you are in the EU, UK, or a country that sets a higher age of digital consent (such as 16), please do not use the App unless you are above that age or have verifiable parental consent.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top and, for material changes, notify you through the App or by email. If we materially change a named AI provider, the photo data shared, or the purpose of that sharing, Mirrorles will request renewed explicit AI Data Sharing Consent before sending new photos under the changed disclosure. Continued use alone does not grant that renewed consent.
11. Business Transfers
If Mirrorles is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, we will notify you through the App or by email before your personal data is transferred and becomes subject to a different privacy policy. The acquiring entity will be required to honor the commitments made in this policy for data transferred to it. You will have the option to delete your account before the transfer takes effect.
12. Contact Us
For privacy questions, data requests, or complaints, email us at:
Mirrorles Privacy
privacy@mirrorles.app